Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51713
Total
4098
Critical
15342
High
14990
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-47418 | HIGH | 8.1 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The project CRUD … | Jul 21, 2026 |
| CVE-2026-47417 | HIGH | 8.1 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The comment endpoints … | Jul 21, 2026 |
| CVE-2026-47416 | CRITICAL | 9.6 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnerable to vertical privilege escalation. The `PATCH /workspaces/{workspace_id}/members/{user_id}` … | Jul 21, 2026 |
| CVE-2026-47415 | HIGH | 8.3 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The issue CRUD … | Jul 21, 2026 |
| CVE-2026-47414 | HIGH | 7.6 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. Five label endpoints … | Jul 21, 2026 |
| CVE-2026-47413 | CRITICAL | 9.6 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have aprivilege escalation / cross-tenant member injection. The `POST … | Jul 21, 2026 |
| CVE-2026-47412 | HIGH | 8.1 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling destructive action. The `DELETE … | Jul 21, 2026 |
| CVE-2026-47411 | MEDIUM | 6.5 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling workspace metadata + settings … | Jul 21, 2026 |
| CVE-2026-44880 | HIGH | 8.8 | A buffer overflow vulnerability was found in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow an remote low-privileged user to … | Jul 21, 2026 |
| CVE-2026-21579 | UNKNOWN | — | This High severity Information Disclosure vulnerability was introduced in versions 7.17.0, 7.19.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. … | Jul 21, 2026 |
| CVE-2026-21577 | UNKNOWN | — | This High severity DoS (Denial of Service) vulnerability was introduced in versions 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data … | Jul 21, 2026 |
| CVE-2026-21575 | HIGH | 7.1 | This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for Windows. This RCE (Remote Code … | Jul 21, 2026 |
| CVE-2026-16493 | HIGH | 7.8 | A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's concrete_artifact_manager.py constructs git clone commands without a '--' (end-of-options) separator before user-supplied URLs when … | Jul 21, 2026 |
| CVE-2026-16439 | UNKNOWN | — | In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer underflow. | Jul 21, 2026 |
| CVE-2026-16243 | UNKNOWN | — | In Eclipse OMR versions up to 0.11, the arraycmp SIMD implementation for Z and P does not check if the number of bytes to compare … | Jul 21, 2026 |
| CVE-2026-47410 | CRITICAL | 9.8 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an insecure default cryptographic key. The JWT signing … | Jul 21, 2026 |
| CVE-2026-47409 | HIGH | 8.1 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling owner lockout. The `DELETE … | Jul 21, 2026 |
| CVE-2026-47408 | MEDIUM | 6.5 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The `GET /workspaces/{workspace_id}/issues/{issue_id}/activity` … | Jul 21, 2026 |
| CVE-2026-47407 | UNKNOWN | — | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the Platform server exposes resources under `/api/v1/workspaces/{workspace_id}/...` and protects … | Jul 21, 2026 |
| CVE-2026-47406 | HIGH | 8.1 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The dependency endpoints … | Jul 21, 2026 |
| CVE-2026-47405 | HIGH | 8.8 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have a broken workspace authorization check that allows any … | Jul 21, 2026 |
| CVE-2026-47399 | HIGH | 8.8 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the workspace-scoped REST routes contain a systemic object-level authorization … | Jul 21, 2026 |
| CVE-2026-47398 | HIGH | 8.1 | PraisonAI is a multi-agent teams system. The v4.6.32 chokepoint refactor (which patched CVE-2026-44334 / GHSA-xcmw-grxf-wjhj) added the PRAISONAI_ALLOW_LOCAL_TOOLS env-var gate to the tool_override.py sinks. However, … | Jul 21, 2026 |
| CVE-2026-47397 | UNKNOWN | — | PraisonAI is a multi-agent teams system. Prior to version 4.6.40, hidden metadata in a webpage causes PraisonAI agents to write attacker-controlled content to arbitrary paths. … | Jul 21, 2026 |
| CVE-2026-44907 | HIGH | 7.5 | A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU usage; … | Jul 21, 2026 |